Severe Risk
IP 2.57.122.177, registered in Romania and operated by Unmanaged Ltd under ASN AS47890, is a critical-risk address with a threat level of 10/10, supported by 13,130 abuse reports from 20 independent automated honeypot sensors spanning October 2025 through June 2026. This IP presents an active and sustained intrusion threat with a confidence score of 85% and an activity frequency rated 8/10, indicating persistent, ongoing hostile operations rather than isolated probing.
The overwhelming majority of reported activity centres on SSH-based intrusion attempts, accounting for the dominant share of 13,130 total reports across categories including brute-force attacks, direct hacking activity, and confirmed exploitation of SSH services. Detection data shows this address repeatedly attempting to establish SSH sessions on non-standard ports, systematically cycling through authentication attempts, and in multiple confirmed instances successfully compromising target systems. The consistent pattern of brute-force attempts combined with active session establishment on unexpected ports signals a deliberate, automated campaign to gain unauthorized remote access to servers worldwide.
For any exposed SSH service, a source generating this volume and variety of authentication attacks poses severe risk of server compromise, data exfiltration, and lateral movement within networks. The confirmed exploitation incidents indicate this IP has successfully breached poorly secured systems, transforming them into further attack infrastructure. Site operators running publicly accessible SSH daemons face immediate credential theft risk if basic hardening measures are absent.
Operators should block this IP at the network perimeter firewall, implement fail2ban or equivalent tools to automatically ban repeat offenders after failed authentication thresholds, and enforce key-based SSH authentication while disabling password authentication entirely. Moving SSH to a non-standard port reduces automated targeting, disabling root login eliminates a high-value target, and enabling multi-factor authentication renders credential-based attacks ineffective regardless of attack volume.